Vulnerability record · CVE-2022-36098 · published 8 September 2022
CVE-2022-36098: XWiki Mentions UI stored XSS via mention and macro fields
Xwiki · Xwiki
XWiki Platform Mentions UI allows JavaScript or Groovy scripts to be stored in a mention, macro anchor, or reference field. The stored code executes for anyone who visits the page containing the mention, making it a persistent cross-site scripting flaw. It affects versions from 12.5-rc-1 before 13.10.6 and 14.4, and is patched in 14.4 and 13.10.6.
Description
XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor, or reference field. The stored code is executed by anyone visiting the page with the mention. This issue has been patched on XWiki 14.4 and 13.10.6. As a workaround, one may update `XWiki.Mentions.MentionsMacro` and edit the `Macro code` field of the `XWiki.WikiMacroClass` XObject.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 3.1 base score is 9.0 (critical) with high confidentiality, integrity, and availability impact, and EPSS is 0.71043 at the 99.37th percentile.
What it is
XWiki Platform Mentions UI allows JavaScript or Groovy scripts to be stored in a mention, macro anchor, or reference field. The stored code executes for anyone who visits the page containing the mention, making it a persistent cross-site scripting flaw. It affects versions from 12.5-rc-1 before 13.10.6 and 14.4, and is patched in 14.4 and 13.10.6.
Impact
An attacker with a low-privileged account can plant script that runs in the browser of every user viewing the affected page, enabling session theft, actions as the victim, or further compromise of the wiki. Because the scope is changed, the injected code can affect resources beyond the vulnerable component.
Attack surface
Reached over the network through wiki content that includes a mention, macro anchor, or reference field; the attacker needs a low-privileged authenticated account to store the payload, and a victim must visit the page for execution.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.71043 (99.37th percentile) and the advisory and Jira references are tagged Exploit, indicating public exploit information exists.
What to do
- Upgrade XWiki Platform to 14.4 or 13.10.6 or later.
- If immediate upgrade is not possible, apply the documented workaround by updating XWiki.Mentions.MentionsMacro and editing the Macro code field of the XWiki.WikiMacroClass XObject.
- Restrict who can create or edit wiki content containing mentions, macro anchors, and reference fields.
- Review and sanitize existing mentions and macro fields for stored script content.
- Monitor vendor advisories for further guidance on this issue.
Detection
- Search wiki content and page history for mention, macro anchor, or reference fields containing script tags or Groovy code.
- Alert on edits to XWiki.Mentions.MentionsMacro or the XWiki.WikiMacroClass XObject Macro code field.
- Monitor web logs and application logs for requests to pages with mentions that correlate with unexpected script execution or user session anomalies.
- Audit accounts with low privileges that create or modify mentions for suspicious payload patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/xwiki/xwiki-platform/commit/4032dc896857597efd169966dc9e2752a9fdd459#diff-4fe22885f772e47d3561a05348f | PatchThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/commit/4f290d87a8355e967378a1ed6aee23a06ba162eb | PatchThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-c5v8-2q4r-5w9v | ExploitPatchThird Party Advisory |
| https://jira.xwiki.org/browse/XWIKI-19752 | ExploitVendor Advisory |
| https://github.com/xwiki/xwiki-platform/commit/4032dc896857597efd169966dc9e2752a9fdd459#diff-4fe22885f772e47d3561a05348f | PatchThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/commit/4f290d87a8355e967378a1ed6aee23a06ba162eb | PatchThird Party Advisory |
| https://github.com/xwiki/xwiki-platform/security/advisories/GHSA-c5v8-2q4r-5w9v | ExploitPatchThird Party Advisory |
| https://jira.xwiki.org/browse/XWIKI-19752 | ExploitVendor Advisory |
Track CVE-2022-36098 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36098), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.